Robust or Private? Adversarial Training Makes Models More Vulnerable to Privacy Attacks